dependabot[bot] opened a new pull request, #2829: URL: https://github.com/apache/shiro/pull/2829
Bumps the maven-dependencies group with 13 updates: | Package | From | To | | --- | --- | --- | | [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.0.6` | `5.0.7` | | [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.0.6` | `5.0.7` | | [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.10` | `1.18.11` | | [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.10` | `1.18.11` | | org.apache.logging.log4j:log4j-slf4j2-impl | `2.26.0` | `2.26.1` | | org.apache.logging.log4j:log4j-core-test | `2.26.0` | `2.26.1` | | org.apache.logging.log4j:log4j-api | `2.26.0` | `2.26.1` | | org.apache.logging.log4j:log4j-core | `2.26.0` | `2.26.1` | | org.apache.logging.log4j:log4j-jul | `2.26.0` | `2.26.1` | | org.apache.logging.log4j:log4j-to-slf4j | `2.26.0` | `2.26.1` | | [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm) | `7.4.3.Final` | `7.4.4.Final` | | [org.codehaus.gmavenplus:gmavenplus-plugin](https://github.com/groovy/GMavenPlus) | `5.0.0` | `5.1.0` | | [com.flowlogix.depchain:integration-test](https://github.com/flowlogix/depchain) | `125` | `127` | Updates `org.apache.groovy:groovy-all` from 5.0.6 to 5.0.7 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/groovy/commits">compare view</a></li> </ul> </details> <br /> Updates `org.apache.groovy:groovy` from 5.0.6 to 5.0.7 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/groovy/commits">compare view</a></li> </ul> </details> <br /> Updates `org.apache.groovy:groovy` from 5.0.6 to 5.0.7 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/groovy/commits">compare view</a></li> </ul> </details> <br /> Updates `net.bytebuddy:byte-buddy` from 1.18.10 to 1.18.11 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/releases">net.bytebuddy:byte-buddy's releases</a>.</em></p> <blockquote> <h2>Byte Buddy 1.18.11</h2> <ul> <li>Add SBOM to published artifacts.</li> <li>Check for traversable paths injected into class files as a rather hypothetical attack vector.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md">net.bytebuddy:byte-buddy's changelog</a>.</em></p> <blockquote> <h3>2. July 2026: version 1.18.11</h3> <ul> <li>Add SBOM to published artifacts.</li> <li>Check for traversable paths injected into class files as a rather hypothetical attack vector.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raphw/byte-buddy/commit/88dd0a324b9479b39a50344865005ffb95b59f93"><code>88dd0a3</code></a> [publish] Releasing Byte Buddy 1.18.11</li> <li><a href="https://github.com/raphw/byte-buddy/commit/46fcadee820662ab1849777386a23ee82bc23b57"><code>46fcade</code></a> [release] Release new version</li> <li><a href="https://github.com/raphw/byte-buddy/commit/6a68de698f33468bc74cd7371b86232fee2ef5b8"><code>6a68de6</code></a> Prevent path traversal from crafted type names when writing class files to fo...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/9ba4ab61e3c3bda09c399dff1646e2a1c7f9e064"><code>9ba4ab6</code></a> Pin ClusterFuzzLite base image and actions by hash.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/dd4f81e5e2be3d2741af2f404f12928502d8eb85"><code>dd4f81e</code></a> Add SBOM to build.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/7dd9a0dd50045140f7e8245ae117f3f9ff9b1ae3"><code>7dd9a0d</code></a> Update internal Byte Buddy and release notes</li> <li><a href="https://github.com/raphw/byte-buddy/commit/d6b3e1512e164719a89d579582031ea84d2e86a9"><code>d6b3e15</code></a> [publish] Start next development iteration 1.18.11-SNAPSHOT</li> <li>See full diff in <a href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.10...byte-buddy-1.18.11">compare view</a></li> </ul> </details> <br /> Updates `net.bytebuddy:byte-buddy-agent` from 1.18.10 to 1.18.11 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/releases">net.bytebuddy:byte-buddy-agent's releases</a>.</em></p> <blockquote> <h2>Byte Buddy 1.18.11</h2> <ul> <li>Add SBOM to published artifacts.</li> <li>Check for traversable paths injected into class files as a rather hypothetical attack vector.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md">net.bytebuddy:byte-buddy-agent's changelog</a>.</em></p> <blockquote> <h3>2. July 2026: version 1.18.11</h3> <ul> <li>Add SBOM to published artifacts.</li> <li>Check for traversable paths injected into class files as a rather hypothetical attack vector.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raphw/byte-buddy/commit/88dd0a324b9479b39a50344865005ffb95b59f93"><code>88dd0a3</code></a> [publish] Releasing Byte Buddy 1.18.11</li> <li><a href="https://github.com/raphw/byte-buddy/commit/46fcadee820662ab1849777386a23ee82bc23b57"><code>46fcade</code></a> [release] Release new version</li> <li><a href="https://github.com/raphw/byte-buddy/commit/6a68de698f33468bc74cd7371b86232fee2ef5b8"><code>6a68de6</code></a> Prevent path traversal from crafted type names when writing class files to fo...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/9ba4ab61e3c3bda09c399dff1646e2a1c7f9e064"><code>9ba4ab6</code></a> Pin ClusterFuzzLite base image and actions by hash.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/dd4f81e5e2be3d2741af2f404f12928502d8eb85"><code>dd4f81e</code></a> Add SBOM to build.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/7dd9a0dd50045140f7e8245ae117f3f9ff9b1ae3"><code>7dd9a0d</code></a> Update internal Byte Buddy and release notes</li> <li><a href="https://github.com/raphw/byte-buddy/commit/d6b3e1512e164719a89d579582031ea84d2e86a9"><code>d6b3e15</code></a> [publish] Start next development iteration 1.18.11-SNAPSHOT</li> <li>See full diff in <a href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.10...byte-buddy-1.18.11">compare view</a></li> </ul> </details> <br /> Updates `net.bytebuddy:byte-buddy-agent` from 1.18.10 to 1.18.11 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/releases">net.bytebuddy:byte-buddy-agent's releases</a>.</em></p> <blockquote> <h2>Byte Buddy 1.18.11</h2> <ul> <li>Add SBOM to published artifacts.</li> <li>Check for traversable paths injected into class files as a rather hypothetical attack vector.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md">net.bytebuddy:byte-buddy-agent's changelog</a>.</em></p> <blockquote> <h3>2. July 2026: version 1.18.11</h3> <ul> <li>Add SBOM to published artifacts.</li> <li>Check for traversable paths injected into class files as a rather hypothetical attack vector.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raphw/byte-buddy/commit/88dd0a324b9479b39a50344865005ffb95b59f93"><code>88dd0a3</code></a> [publish] Releasing Byte Buddy 1.18.11</li> <li><a href="https://github.com/raphw/byte-buddy/commit/46fcadee820662ab1849777386a23ee82bc23b57"><code>46fcade</code></a> [release] Release new version</li> <li><a href="https://github.com/raphw/byte-buddy/commit/6a68de698f33468bc74cd7371b86232fee2ef5b8"><code>6a68de6</code></a> Prevent path traversal from crafted type names when writing class files to fo...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/9ba4ab61e3c3bda09c399dff1646e2a1c7f9e064"><code>9ba4ab6</code></a> Pin ClusterFuzzLite base image and actions by hash.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/dd4f81e5e2be3d2741af2f404f12928502d8eb85"><code>dd4f81e</code></a> Add SBOM to build.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/7dd9a0dd50045140f7e8245ae117f3f9ff9b1ae3"><code>7dd9a0d</code></a> Update internal Byte Buddy and release notes</li> <li><a href="https://github.com/raphw/byte-buddy/commit/d6b3e1512e164719a89d579582031ea84d2e86a9"><code>d6b3e15</code></a> [publish] Start next development iteration 1.18.11-SNAPSHOT</li> <li>See full diff in <a href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.10...byte-buddy-1.18.11">compare view</a></li> </ul> </details> <br /> Updates `org.apache.logging.log4j:log4j-slf4j2-impl` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-core-test` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-api` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-core` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-jul` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-to-slf4j` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-core-test` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-api` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-core` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-jul` from 2.26.0 to 2.26.1 Updates `org.apache.logging.log4j:log4j-to-slf4j` from 2.26.0 to 2.26.1 Updates `org.hibernate.orm:hibernate-core` from 7.4.3.Final to 7.4.4.Final <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/hibernate/hibernate-orm/releases">org.hibernate.orm:hibernate-core's releases</a>.</em></p> <blockquote> <h2>Release 7.4.4</h2> <h1>Hibernate ORM 7.4.4.Final released</h1> <p>Today, we published a new release of Hibernate ORM 7.4: 7.4.4.Final.</p> <p>You can find the full list of 7.4.4.Final changes <a href="https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HHH%20AND%20fixVersion%20%3D%207.4.4">here</a>.</p> <h2>What's new</h2> <ul> <li>See the <a href="https://hibernate.org/orm/releases/7.4">website</a> for requirements and compatibilities.</li> <li>See the <a href="https://docs.hibernate.org/orm/7.4/whats-new/whats-new.html">What's New</a> guide for details about new features and capabilities.</li> <li>See the <a href="https://docs.hibernate.org/orm/7.4/migration-guide/">Migration Guide</a> for details about migration.</li> </ul> <h2>Conclusion</h2> <p>For additional details, see:</p> <ul> <li>the <a href="https://hibernate.org/orm/releases/7.4/">release page</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/migration-guide/">Migration Guide</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/introduction/html_single/">Introduction Guide</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/userguide/html_single/">User Guide</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/javadocs">API docs</a></li> </ul> <p>See also the following resources related to supported APIs:</p> <ul> <li>the <a href="https://hibernate.org/community/compatibility-policy/">compatibility policy</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/incubating/incubating.txt">incubating API report</a> (<code>@Incubating</code>)</li> <li>the <a href="https://docs.hibernate.org/orm/7.4/deprecated/deprecated.txt">deprecated API report</a> (<code>@Deprecated</code> + <code>@Remove</code>)</li> <li>the <a href="https://docs.hibernate.org/orm/7.4/internals/internal.txt">internal API report</a> (internal packages, <code>@Internal</code>)</li> </ul> <p>Visit the <a href="https://hibernate.org/community/">website</a> for details on getting in touch with us.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/hibernate/hibernate-orm/blob/7.4.4/changelog.txt">org.hibernate.orm:hibernate-core's changelog</a>.</em></p> <blockquote> <h2>Changes in 7.4.4.Final (July 05, 2026)</h2> <p><a href="https://hibernate.atlassian.net/projects/HHH/versions/39929">https://hibernate.atlassian.net/projects/HHH/versions/39929</a></p> <p>** Bug * HHH-20647 Binding an NClob attribute fails on PostgreSQL with "Could not convert 'java.sql.NClob' to 'java.sql.Clob'" * HHH-20634 Property based id generator configuration no longer working for EmbeddedId * HHH-20633 Unnecessary cast to SessionFactoryImplementor in AuditLogFactory * HHH-20614 AnnotationBasedGenerator is not initialized when the interface is implemented by an (abstract) superclass instead of the concrete class (after upgrading to hibernate 7.3/7.4) * HHH-20586 GlobalRegistrationsImpl is not extracting query hints correctly * HHH-20582 Envers <code>ToOneRelationMetadataGenerator.checkMappedByAudited</code> fails when inverse <code>@OneToOne</code> mappedBy points to a property declared on a superclass <code>@Entity</code> * HHH-20550 SqmSelectStatement.createCountQuery() doesn't copy CTE statements * HHH-20467 StackOverflow with Converters with unbounded Generics * HHH-20318 Unable to update CLOB column * HHH-20146 Cascade delete with bytecode enhancement throws transient exception * HHH-19569 Hibernate 6 alias injection in native query problem when using Joined Inheritance</p> <p>** Task * HHH-20642 Handle renaming of Panache Next to Quarkus Data in hibernate-processor and add name SPI</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/hibernate/hibernate-orm/commit/0f115c4026480c70e9674cb3fdf92362b5025a66"><code>0f115c4</code></a> [Jenkins release job] Preparing release 7.4.4.Final</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/3578615956b24207fdcf9777b93e4440316c1fd1"><code>3578615</code></a> [Jenkins release job] changelog.txt updated by release build 7.4.4.Final</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/0ac8b7127fce945c1316500475b91dc726efc976"><code>0ac8b71</code></a> HHH-20647 Handle Clob unwrap/wrap in NClobJavaType</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/1621b054854471fa1f552387e9afdfce4f57202d"><code>1621b05</code></a> HHH-20318 Fix CCE in Clob/NClob unwrap CharacterStream branch</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/bfd89d8bb98acc9f6e14ed5f6e8cd0d89810a3cf"><code>bfd89d8</code></a> HHH-20622 locate() with start position returns wrong value when pattern is no...</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/e1871682ce9418031093d02eed206f1311874154"><code>e187168</code></a> HHH-20467 Resolve type variables to bounds when context is not parameterized</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/057a02609a10e27990f61a1ad9ccf63b4b3b078a"><code>057a026</code></a> HHH-20146: Fix multi-level cascade delete with bytecode enhancement</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/c23d31a6f91b757b8365c27ea55eddcce6051664"><code>c23d31a</code></a> HHH-20582 Accommodate PR feedback in tests</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/68a0f61fe0aa531de6053622558db020de2960cf"><code>68a0f61</code></a> HHH-20582 Walk superclass auditing data when resolving <a href="https://github.com/OneToOne"><code>@OneToOne</code></a> mappedBy</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/86c220c7b593df21b433f07606b02806d0844b18"><code>86c220c</code></a> HHH-20642 Extract Quarkus Data type names into a ServiceLoader SPI</li> <li>Additional commits viewable in <a href="https://github.com/hibernate/hibernate-orm/compare/7.4.3...7.4.4">compare view</a></li> </ul> </details> <br /> Updates `org.codehaus.gmavenplus:gmavenplus-plugin` from 5.0.0 to 5.1.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/groovy/GMavenPlus/releases">org.codehaus.gmavenplus:gmavenplus-plugin's releases</a>.</em></p> <blockquote> <h2>5.1.0</h2> <h2>Bugs</h2> <ul> <li>fix: Use Maven source-root removal APIs (<a href="https://redirect.github.com/groovy/GMavenPlus/issues/341">#341</a>)</li> <li>Drop warnings about missing dependencies down to debug (<a href="https://redirect.github.com/groovy/GMavenPlus/issues/390">#390</a>)</li> </ul> <h2>Enhancements</h2> <ul> <li>Add to Java 25 enum LanguageLevel by <a href="https://github.com/jonesbusy"><code>@jonesbusy</code></a> in <a href="https://redirect.github.com/groovy/GMavenPlus/issues/346">#346</a></li> <li>feat: Honor compiler release for Groovy bytecode (<a href="https://redirect.github.com/groovy/GMavenPlus/issues/387">#387</a>)</li> </ul> <h2>Potentially breaking changes</h2> <p>None.</p> <h2>Notes</h2> <p>None.</p> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/jonesbusy"><code>@jonesbusy</code></a> made their first contribution in <a href="https://redirect.github.com/groovy/GMavenPlus/issues/346">#346</a></li> </ul> <h2>Full Changelog</h2> <p><a href="https://github.com/groovy/GMavenPlus/compare/5.0.0...5.1.0">https://github.com/groovy/GMavenPlus/compare/5.0.0...5.1.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/groovy/GMavenPlus/commit/33ac4f5d495bd08189ba4744fd6d831a20d7d2cf"><code>33ac4f5</code></a> [maven-release-plugin] prepare release 5.1.0</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/fadc578b4f7bd6e992c2ad6af1025bd43a8a2710"><code>fadc578</code></a> Merge pull request <a href="https://redirect.github.com/groovy/GMavenPlus/issues/391">#391</a> from groovy/adjust-dependency-logging</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/2180de9b4a9d04f5e0b1bc5211263418fce758ef"><code>2180de9</code></a> Drop warnings about missing dependencies down to debug (closes <a href="https://redirect.github.com/groovy/GMavenPlus/issues/390">#390</a>)</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/3991ff8975af37c1b6f04a63069dd8c032ed319e"><code>3991ff8</code></a> Merge pull request <a href="https://redirect.github.com/groovy/GMavenPlus/issues/389">#389</a> from groovy/feat/honor-compiler-release</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/3d29b11f9167cacbe605da14d46984a27833b51c"><code>3d29b11</code></a> feat: Honor compiler release for Groovy bytecode (closes <a href="https://redirect.github.com/groovy/GMavenPlus/issues/387">#387</a>)</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/b7bb980c645ccb9087eeb7c9a82e8d8335fce99c"><code>b7bb980</code></a> build: Bump version</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/5622987ace2d306580c11c4dfadd8610f16487c6"><code>5622987</code></a> doc: Update redeploy instructions</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/0951225afcbdbd09451b37cc642411a719dacc54"><code>0951225</code></a> doc: Add a skill for updating everything</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/e510e4540dd38eda47b67336f408a124defd221c"><code>e510e45</code></a> doc: Add a skill for updating everything</li> <li><a href="https://github.com/groovy/GMavenPlus/commit/aec8eb1348ef552626be867d006765203d1224de"><code>aec8eb1</code></a> doc: Update developer documentation</li> <li>Additional commits viewable in <a href="https://github.com/groovy/GMavenPlus/compare/5.0.0...5.1.0">compare view</a></li> </ul> </details> <br /> Updates `com.flowlogix.depchain:integration-test` from 125 to 127 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/flowlogix/depchain/commits">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
